Patients notified that their information was involved in Onsite Mammography’s October 2024 email-account breach have until August 11, 2026, to claim settlement benefits. The largest cash option reimburses as much as $5,000, but only for documented out-of-pocket losses tied to the incident. With the court’s approval hearing still ahead, the deadline is for filing a claim, not a promise that money will arrive immediately.
The $5,000 figure is a reimbursement ceiling
The proposed $2.525 million settlement covers people in the United States whose private information may have been affected and who received written notice from Onsite Mammography, which does business as Onsite Women’s Health. The underlying incident involved unauthorized access to one employee email account. Onsite denies wrongdoing and liability, and the court has not decided the merits of the claims.
The official settlement FAQ says the fund can reimburse unreimbursed costs, losses, or expenditures up to $5,000 for eligible class members. The amount is not a flat award. A claimant seeking the maximum must show actual losses connected to the incident, and the administrator can reject expenses that lack documentation or were already repaid by another source.
The settlement also offers a pro rata cash payment and three years of credit and medical-data monitoring. The flat payment will depend on the fund remaining after administration, court-approved fees, and valid claims, so its final amount is not guaranteed in advance. Claimants must choose the benefit path that matches their records rather than treating the largest advertised number as the standard check.
Free retirement updates: Every year, billions in settlements and unclaimed money go unclaimed. Our free Retirement Shield newsletter sends the real ones — with deadlines — a couple times a week. Get the free newsletter.
Eligibility begins with the breach notice
The class definition is narrower than everyone who ever received a mammogram at an affiliated site. It covers individuals whose private information may have been impacted and who received written notice from the defendant. The notice typically contains identifiers used by the administrator, making it the best starting point for confirming eligibility and filing through the authorized portal.
The official settlement website says submitting a claim by August 11 is the only way to receive the pro rata cash payment or monitoring benefit. Doing nothing produces no payment or monitoring and can still release covered legal claims if the settlement becomes final. The earlier exclusion deadline has passed, but the claim window remained open when rechecked on August 9.
A documented-loss claim should connect each expense to the data incident. Bank statements, invoices, receipts, fraud correspondence, and records of identity-protection costs carry more weight than a general assertion that the breach was upsetting. The settlement is compensating economic loss under negotiated terms; it is not paying $5,000 merely because personal information appeared in an affected account.
Court approval comes after the claim cutoff
The final approval hearing is scheduled for September 9, 2026, after claims close. The judge will decide whether the settlement is fair and whether requested fees and awards should be approved. Even after approval, appeals can delay distribution. A valid claim reserves a place in the process; it does not create a fixed payment date.
The official site’s court-documents section contains the notice, agreement, and approval filings that control over third-party summaries. That distinction matters during a short claim window, because copied settlement listings can omit eligibility limits or describe the maximum documented benefit as though it were an automatic payment.
The pro rata option is funded from the same settlement pool that pays administration, attorney fees, service awards, monitoring, and documented-loss claims. Its value can therefore change with participation and court-approved deductions. A class member with no economic loss is not guaranteed a particular flat dollar amount, while a person choosing reimbursement is limited by both actual supported harm and the $5,000 ceiling.
Medical-data monitoring is distinct from ordinary credit monitoring because compromised health information can be used for fraudulent treatment, insurance billing, or prescription activity that does not appear on a credit report. The settlement’s three-year service addresses both credit and medical-data risks. A claimant can weigh that protection separately from cash, especially when the affected information involved more than contact details.
The filing channel should be confirmed from the authorized domain before notice credentials are entered. Settlement deadlines attract imitation sites that copy case names and benefit amounts. The genuine administrator does not charge a filing fee, and a request to pay money, disclose an online-banking password, or buy a service to unlock the claim is inconsistent with the court-supervised process.
A confirmation page, email, or mailed tracking record can establish that the claim was submitted on time. That proof matters when the deadline is only two days away and the administrator later asks for missing documentation. Filing early enough to correct an error is preferable, but preserving the submission record at least prevents a technical dispute over whether the August 11 cutoff was met.
The August 11 date is the immediate financial fact. Eligible patients with documented losses have a path to seek up to $5,000, while those without such losses may pursue the pro rata option and monitoring. The settlement may take months to clear the court, but no later approval can revive a claim that missed the administrator’s filing deadline.
This article was produced with AI assistance and reviewed by The Money Overview editorial team.
More Financial Reading